What is CVE-2026-70615?
boringproxy up to version 0.10.0 contains a newline injection vulnerability allowing authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file. This can enable unauthorized access to the server. Affected users should update boringproxy and restrict network access to mitigate the risk.
Azərbaycanca: boringproxy-nin 0.10.0 və əvvəlki versiyalarında authenticated istifadəçilərin SSH authorized_keys faylına newline injection zəifliyi aşkarlanıb. Bu, tunnel yaratmaq icazəsi olan aşağı səviyyəli istifadəçilərə server hesabına icazəsiz giriş əldə etməyə imkan verir. Təsirlənən sistemlərdə boringproxy-i son versiyaya yeniləmək və şəbəkə girişlərini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of boringproxy are affected by CVE-2026-70615?
This vulnerability affects boringproxy up to and including version 0.10.0.
What privileges does an attacker need to exploit this vulnerability?
The attacker must be an authenticated low-privileged user with tunnel-creation permission in boringproxy.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.